US2006041669A1PendingUtilityA1
Securing web services
Est. expiryMay 19, 2024(expired)· nominal 20-yr term from priority
H04L 63/0807H04L 63/08H04L 63/10
42
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A scalable policy-based Web Services security architecture that incorporates a combination of authentication with service discovery, evaluation of access policies, and capturing the result of this process in a signed, security token, thus, allowing efficient processing for each service request in a secure manner. A method for securing a Web Service comprises discovering the Web Service in response to a service request and determining an access policy for the Web Service separately from the actual service based on the service request.
Claims
exact text as granted — not AI-modified1 . A method for securing a Web Service, the method comprising:
discovering the Web Service in response to a service request; and determining an access policy for the Web Service separately from the actual service based on the service request.
2 . A method for securing a Web Service, the method comprising:
sending one or more invocations to the Web Service after discovering the Web Service.
3 . A method, as set forth in claim 1 , wherein determining the access policy for the Web Service separately from the actual service based on the service request further comprises:
using a pre-computed policy.
4 . A method, as set forth in claim 3 , wherein using a pre-computed policy further comprises:
evaluating access policies for the Web Service to determine identity and access policy information; and encoding the identity and access policy information in a security token based on said pre-computed policy.
5 . A method, as set forth in claim 4 , wherein encoding the identity and access policy information in a security token further comprises:
using a signed security token with each subsequent service request.
6 . A computer readable medium comprising programming instructions for a web server coupled to a network for serving service requests, the web server linked to a plurality of clients, the programming instructions comprising:
discovering the Web Service in response to a service request; and determining an access policy for the Web Service separately from the actual service based on the service request.
7 . The computer readable medium according to claim 6 , further comprising instructions for:
sending one or more invocations to the Web Service after discovering the web service.
8 . The computer readable medium according to claim 6 , further comprising instructions for:
using a pre-computed policy.
9 . The computer readable medium according to claim 7 , further comprising instructions for:
evaluating access policies for the Web Service to determine identity and access policy information; and encoding the identity and access policy information in a security token based on said pre-computed policy.
10 . The computer readable medium according to claim 9 , further comprising instructions for:
using a signed security token with each subsequent service request.
11 . A web server for serving Web Services to a plurality of clients linked via a network therewith, the web server comprising:
an interface coupled to a cache for storing identity and access policy information; an access controller including a policy engine to evaluate access policies and encode its decision in a security token; and a module for securing a Web Service based on an access policy determined for the Web Service separately from the actual service based on a service request.
12 . A web server according to claim 11 , wherein the module to discover the Web Service in response to the service request.
13 . A web server according to claim 11 , wherein the module to send one or more invocations to the Web Service after discovering the Web Service.
14 . A web server according to claim 11 , wherein the module to use a pre-computed policy.
15 . A web server according to claim 11 , wherein the module to capture the security token in a signed security token for use with each subsequent service request.
16 . A system for securing a Web Service, the system comprising:
a client that sends a service request for a Web Service over a network; and a web server coupled to said network to serve the Web Service across different administrative domains based on a pre-computed policy.
17 . A system for securing a Web Service; wherein the web server further comprises:
an interface coupled to a cache for storing identity and access policy information.
18 . A system for securing a Web Service, wherein the web server further comprises:
an access controller including a policy engine to evaluate access policies and encode its decision in a security token.
19 . A system for securing a Web Service, wherein the web server further comprises:
a module for securing a Web Service based on an access policy determined for the Web Service separately from the actual service based on a service request.
20 . A system for securing a Web Service, as set forth in claim 19 , wherein the module to discover the Web Service in response to the service request.
21 . A method on a server linked to a network of a plurality of clients, the method comprising:
receiving a service request from a client; using a first access controller element to discover a service in response to the service request; and using a second access controller element which separates access control enforcement from the actual service based on the service request.
22 . A method, as set forth in claim 21 , wherein using a first access controller element to discover a service further comprises:
performing authentication of the service request; calculating access policy for the service; and caching authentication and access policy evaluations.
23 . A method, as set forth in claim 21 , wherein caching authentication and access policy evaluations further comprises:
encoding identity and access policy information in a signed access token; and detecting a service invocation.
24 . A method, as set forth in claim 23 , wherein detecting a service invocation further comprises:
in response to a service invocation, passing the signed access token to an access controller; and reusing the authentication and access policy calculations.
25 . A method as set forth in claim 24 , wherein reusing the authentication and access policy calculations further comprises:
enabling use of a standard Web Service across different administrative domains.Join the waitlist — get patent alerts
Track US2006041669A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.